blog-scraper
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: RSS scraping behavior is aligned with the stated purpose and uses a standard PyPI dependency, but the optional fallback relies on an unpinned third-party Apify Store actor outside the publisher's control. The requested Apify token is proportionate, yet forwarding it into community-hosted actor execution raises medium supply-chain and credential-forwarding risk.
Confidence: 85%Severity: 58%
Audit Metadata